Who is asking, and why. Breakwater Cyber Corp sells one thing: we supply the named Cybersecurity Officer a regulated facility must designate under 33 CFR 101.625, and we do the compliance work the rule assigns to that role. This Check is free and is not conditional on buying anything. We built it because a facility that knows which obligations attach to it is a facility that can decide what to do about them, including doing it themselves. You can reach us at contact [at] breakwatercybercorp [dot] com.
If a letter brought you here. We wrote to a number of facility operators about this rule. The letter pointed at this site rather than at this page, so if you arrived from it, this is the Check it referred to.
What we do not ask. Nothing about your systems, your configuration, your network, your vulnerabilities or anything that failed a scan. Every question below asks whether a requirement is met, not how anything works. We do not want that information at this stage, and we have not built anywhere to put it.
It runs entirely in your browser. Your answers are not sent to us unless you choose to send them at the end, and you can confirm that in your browser’s network tab.
We count visits with Google Analytics, and your answers are not part of it. Like most sites we measure how many people arrive and how far they get, using Google Tag Manager and Google Analytics. That records pages and events, not the answers you give below: nothing you enter in the Check is sent anywhere unless you use the form at the end. You can confirm that in your browser’s network tab.
The questions
Answer these against your own facility. Below them is the full set of Subpart F requirements.
What 33 CFR 101 Subpart F requires
Subpart F applies to the owners and operators of U.S.-flagged vessels, facilities and OCS facilities required to have a security plan under 33 CFR Parts 104, 105 and 106 (ยง101.605(a)). That includes facilities operating under an approved Alternative Security Program under ยง105.140.
- Cybersecurity training for all personnel with access to IT or OT systems, including contractors, and additional training for key personnel. ยง101.650(d) โ from 12 January 2026, and annually thereafter (ยง101.650(d)(4))
- A Cybersecurity Assessment addressing each covered vessel, facility and OCS facility. ยง101.650(e)(1) โ no later than 16 July 2027, and annually thereafter
- A Cybersecurity Plan containing the fourteen sections the rule lists. ยง101.630(c)
- Submission of the Cybersecurity Plan to the Coast Guard for review and approval. ยง101.655 โ no later than 16 July 2027
- Designate a Cybersecurity Officer in writing, by name and by title, accessible to the Coast Guard 24 hours a day, 7 days a week, and identify how they can be contacted at any time. ยง101.620(b)(3)
- The Cybersecurity Officer carries the fifteen duties the rule attaches to the role. ยง101.625(d)
- The Cybersecurity Officer must have general knowledge, through training, education or equivalent job experience, in the twelve areas the rule lists. ยง101.625(e)
- A Cyber Incident Response Plan, developed, approved, executed and exercised. ยง101.620(b)(6) ยท ยง101.625(d)(4)
- Reportable cyber incidents recorded and reported to the owner or operator, and reported by the owner or operator to the National Response Center. ยง101.625(d)(10) ยท ยง101.620(b)(7)
- Records created and maintained for training, drills, exercises, cybersecurity threats, reportable cyber incidents and audits of the Plan. ยง101.640
- Cybersecurity drills at least twice each calendar year. ยง101.635(b)(1)
- A cybersecurity exercise at least once each calendar year, with no more than 18 months between exercises, including the substantial and active participation of the Cybersecurity Officer. ยง101.635(c)(1), (c)(5)
- An annual audit of the Plan and its implementation. Personnel conducting it must not have regularly assigned cybersecurity duties for the facility being audited, and must be independent of the measures audited. §101.630(f)(1) assigns this one to the Cybersecurity Officer by name rather than to the owner or operator: the CySO must ensure the audit is performed, and the CySO must attach a report to the Plan certifying that the Plan meets the applicable requirements of this subpart. ยง101.630(f)(1), (f)(4)
- A penetration test in conjunction with Cybersecurity Plan renewal. ยง101.650(e)(2)
This reports what the rule says. It is not legal advice and it is not a determination of whether the rule applies to your facility โ that is the Coast Guard's. Reflects the rule as at 10 August 2026.
What to do with this
If you are unsure whether the rule reaches your facility, your Sector office is the right place to confirm.
Three of these are harder than they look. The officer has to be reachable by the Coast Guard at any hour of any day, and the annual audit cannot be done by whoever runs the programme. The rule also requires that person to hold general knowledge across twelve areas §101.625(e) — facility operations, the facility’s own Cyber Incident Response Plan, conducting audits and inspections, handling Sensitive Security Information, and current threat patterns and known exploited vulnerabilities among them.
If you would like it in writing, we will send it. If you would like to talk about who does the work, book a call.